Skip to main content
Mallory
1 malware family

UNC5537

Also known asUNC5537

UNC5537 is a financially motivated threat actor tracked by Mandiant and associated with the 2024 Snowflake customer compromises. Mandiant attributed the campaign to UNC5537 and reported that the activity affected roughly 165 Snowflake customer organizations. The actor used stolen credentials obtained from infostealer malware infections to access Snowflake customer environments, with the absence of enforced MFA repeatedly cited as a key enabling factor. Reported infostealers associated with exposed credentials include VIDAR, REDLINE, LUMMA, RISEPRO, RACOON STEALER, and METASTEALER. The group’s activity involved logging into Snowflake customer tenants with valid credentials, often via SnowSight and the SnowSQL CLI, then conducting reconnaissance and large-scale data theft followed by extortion. Mandiant observed UNC5537 using the publicly available database management utility DBeaver Ultimate to connect to and run queries across Snowflake instances. Mandiant also tracked an attacker-named utility, “rapeflake,” as FROSTBITE; observed .NET and Java variants were assessed to perform SQL-based reconnaissance such as enumerating users, roles, IPs, session IDs, and organization names. The campaign was described as relying on customer-side security gaps rather than a Snowflake software vulnerability, specifically missing MFA, unrotated credentials, and lack of network allow-listing. The actor extracted large volumes of sensitive data and extorted victims after exfiltration. Publicly identified victims in the provided content include Ticketmaster, AT&T, Santander, Advance Auto Parts, Neiman Marcus, LendingTree/QuoteWizard, Los Angeles Unified School District, and Pure Storage. The content states that some of the stolen data was later distributed by ShinyHunters, and multiple sources discuss UNC5537 in relation to ShinyHunters. One source describes broader cluster evolution involving UNC5537, UNC6040, UNC6395, and UNC6661 within a ShinyHunters profile, but the provided content does not establish these as formal aliases of UNC5537. Reported pseudonyms used by the actor include “Judische” and “Waifu.” Mandiant reportedly assessed members to be based in North America and Turkey.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics19 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589
Gather Victim Identity Information
T1589.001
Credentials
T1592
Gather Victim Host Information
TA0001
Initial Access
2 techniques
T1078×9
Valid Accounts
T1190
Exploit Public-Facing Application
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
TA0003
Persistence
1 technique
T1078×9
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078×9
Valid Accounts
TA0005
Stealth
1 technique
T1078×9
Valid Accounts
TA0006
Credential Access
1 technique
T1555×5
Credentials from Password Stores
TA0007
Discovery
1 technique
T1087
Account Discovery
TA0009
Collection
2 techniques
T1213×2
Data from Information Repositories
T1530×2
Data from Cloud Storage
TA0011
Command and Control
1 technique
T1219
Remote Access Tools
TA0010
Exfiltration
2 techniques
T1537×2
Transfer Data to Cloud Account
T1567×2
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
T1567.003
Exfiltration to Text Storage Sites
TA0040
Impact
1 technique
T1657×5
Financial Theft
ACTIVITY FEED

Recent activity

10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping15

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

UNC5537 | Mallory